A storage system includes a plurality of storage devices including a plurality of user storage spaces allocated to each of a plurality of users, a controller configured to receive mapping information, which is information about the plurality of user storage spaces, from an external computing device that performs an operation for each of the plurality of users through a plurality of virtual machines, and a memory storing the mapping information, wherein the controller is configured to generate, when receiving the mapping information, different user keys for each of the plurality of user storage spaces, based on the mapping information, and manage user data stored in the plurality of storage devices by using the mapping information and user keys.
Legal claims defining the scope of protection, as filed with the USPTO.
a plurality of storage devices including a plurality of user storage spaces allocated to each of a plurality of users; a controller configured to receive mapping information about the plurality of user storage spaces, from an external computing device configured to perform an operation for each of the plurality of users through a plurality of virtual machines; and wherein the controller is configured to generate a user key for each of the plurality of user storage spaces, based on the mapping information, in response to the controller receiving the mapping information, wherein each user key is unique to each of the plurality of user storage spaces, and wherein the controller is further configured to manage user data stored in the plurality of storage devices by using the mapping information and the user keys. a memory configured to store the mapping information, . A storage system comprising:
claim 1 . The storage system of, wherein the mapping information comprises at least one of user storage space identification information, computing device identification information, virtual machine identification information, storage system identification information, storage device identification information, and logic block address information.
claim 1 . The storage system of, wherein the controller is configured to encrypt write data corresponding to the data write request by using the user keys, and write the encrypted write data to the plurality of storage devices, based on the mapping information, in response to the controller receiving a data write request from the external computing device.
claim 1 . The storage system of, wherein the controller is configured to read encrypted read data corresponding to the data read request, from the plurality of storage devices, based on the mapping information, decrypt the encrypted read data by using the user keys, and transmit the decrypted read data to the external computing device, in response to the controller receiving a data read request from the external computing device.
claim 1 . The storage system of, wherein the controller is configured to determine whether to encrypt the user data using the user keys, based on encryption function usage setting of each of the plurality of users.
claim 1 . The storage system of, wherein the controller is configured to remove the mapping information, the user keys, and the user data corresponding to a user withdrawal request, in response to the controller receiving the user withdrawal request from the external computing device.
claim 1 . The storage system of, wherein the controller is configured to transmit a mapping information request to the external computing device and receive the mapping information from the external computing device in response to the storage system being reset or rebooted.
a plurality of storage devices comprising a plurality of user storage spaces allocated to each of a plurality of users; transmit a mapping information request to an external computing device that performs an operation for each of the plurality of users through a plurality of virtual machines, in response to the storage system being reset or rebooted, receive mapping information about the plurality of user storage spaces, from the external computing device, generate a user key for each of the plurality of user storage spaces, based on the mapping information, wherein each user key is unique to each of the plurality of user storage spaces, and manage user data stored in the plurality of storage devices by using the mapping information and the user keys; and a controller configured to a memory storing the mapping information. . A storage system comprising:
claim 8 . The storage system of, wherein the mapping information comprises at least one of user storage space identification information, computing device identification information, virtual machine identification information, storage system identification information, storage device identification information, and logic block address information.
claim 8 . The storage system of, wherein the controller is configured to encrypt write data corresponding to the data write request by using the user keys, and write the encrypted write data to the plurality of storage devices, based on the mapping information, in response to the controller receiving a data write request from the external computing device.
claim 8 . The storage system of, wherein the controller is configured to read encrypted read data corresponding to the data read request, from the plurality of storage devices, based on the mapping information, decrypt the encrypted read data by using the user keys, and transmit the decrypted read data to the external computing device, in response to the controller receiving a data read request from the external computing device.
claim 8 . The storage system of, wherein the controller is configured to determine whether to encrypt the user data using the user keys, based on encryption function usage setting of each of the plurality of users.
claim 8 . The storage system of, wherein the controller is configured to remove the mapping information, the user keys, and the user data corresponding to a user withdrawal request, in response to the controller receiving the user withdrawal request from the external computing device.
a plurality of storage systems configured to store user data of each of a plurality of users; and a plurality of computing devices configured to perform an operation for each of the plurality of users through a plurality of virtual machines and transmit to the plurality of storage systems, mapping information about a plurality of user storage spaces allocated to each of the plurality of users, a plurality of storage devices comprising the plurality of user storage spaces allocated to each of the plurality of users; a controller configured to generate a user key for each of the plurality of user storage spaces, based on the mapping information, and manage user data stored in the plurality of storage devices by using the mapping information and the user keys, in response to the controller receiving the mapping information, wherein each user key is unique to each of the plurality of user storage spaces; and wherein the plurality of storage systems includes, a memory storing the mapping information. . A cloud system comprising:
claim 14 create a virtual machine in response to receiving a user sign-up request from an external user device, allocate a user storage space inside the plurality of storage systems, generate mapping information, and transmit the mapping information to the plurality of storage systems. . The cloud system of, wherein the plurality of computing devices are configured to
claim 14 . The cloud system of, wherein the mapping information comprises at least one of user storage space identification information, computing device identification information, virtual machine identification information, storage system identification information, storage device identification information, and logic block address information.
claim 14 . The cloud system of, wherein the controller is configured to encrypt write data corresponding to the data write request by using the user keys, and write the encrypted write data to the plurality of storage devices, based on the mapping information, in response to the controller receiving a data write request from the plurality of computing devices.
claim 14 . The cloud system of, wherein the controller is configured to read encrypted read data corresponding to the data read request, from the plurality of storage devices, based on the mapping information, decrypt the encrypted read data by using the user keys, and transmit the decrypted read data to the plurality of computing devices, in response to the controller receiving a data read request from the plurality of computing devices.
claim 14 wherein the controller is configured to remove the mapping information, the user keys, and the user data corresponding to the user withdrawal request, in response to the controller receiving the user withdrawal request. . The cloud system of, wherein the plurality of computing devices are configured to transmit a user withdrawal request to the controller, and
claim 14 wherein the plurality of computing devices are configured to transmit the mapping information to the controller in response to the controller receiving the mapping information request. . The cloud system of, wherein the controller is configured to transmit a mapping information request to the plurality of computing devices in response to the controller receiving the plurality of storage systems are reset or rebooted, and
Complete technical specification and implementation details from the patent document.
This application is based on and claims priority under 35 U.S.C. § 119 to Korean Patent Application No. 10-2023-0167155, filed on Nov. 27, 2023, in the Korean Intellectual Property Office, the disclosure of which is incorporated by reference herein in its entirety.
Inventive concepts relate to a storage system using mapping information.
As non-volatile memory, flash memory may retain stored data even when the power is turned off, and storage devices including flash memory, such as solid-state drives (SSDs) and memory cards, are widely used.
Recently, research is being actively conducted on a large-capacity storage system including a plurality of storage devices in order to provide space for storing data to a plurality of users. Such a storage system may be accessed by a plurality of users, and thus, management and protection of user data stored by a plurality of users are important (or beneficial). To this end, various methods are being developed for storage regions of user data of each of a plurality of users, and methods for encrypting user data.
Various example embodiments of inventive concepts provide a storage system that manages user data by using mapping information.
Some example embodiments of inventive concepts provide a storage system includes a plurality of storage devices including a plurality of user storage spaces allocated to each of a plurality of users, a controller configured to receive mapping information about the plurality of user storage spaces, from an external computing device configured to perform an operation for each of the plurality of users through a plurality of virtual machines, and a memory configured to store the mapping information, wherein the controller is configured to generate different user keys for each of the plurality of user storage spaces, based on the mapping information, in response to the controller receiving the mapping information, and wherein the controller is further configured to manage user data stored in the plurality of storage devices by using the mapping information and the user keys.
Some example embodiments of inventive concepts provide a storage system includes a plurality of storage devices including a plurality of user storage spaces allocated to each of a plurality of users, a controller configured to transmit a mapping information request to an external computing device that performs an operation for each of the plurality of users through a plurality of virtual machines, in response to the storage system being reset or rebooted, receive mapping information about the plurality of user storage spaces, from the computing device, generate different user keys for each of the plurality of user storage spaces, based on the mapping information, and manage user data stored in the plurality of storage devices by using the mapping information and the user keys, and a memory storing the mapping information.
Some example embodiments of inventive concepts provide a cloud system includes a plurality of storage systems configured to store user data of each of a plurality of users, and a plurality of computing devices configured to perform an operation for each of the plurality of users through a plurality of virtual machines and transmit to the plurality of storage systems, mapping information about a plurality of user storage spaces allocated to each of the plurality of users, wherein the plurality of storage systems include a plurality of storage devices including the plurality of user storage spaces allocated to each of the plurality of users, a controller configured to generate different user keys for each of the plurality of user storage spaces, based on the mapping information, and manage user data stored in the plurality of storage devices by using the mapping information and the user keys, in response to the controller receiving the mapping information, and a memory storing the mapping information.
Hereinafter, various example embodiments of inventive concepts will be described in detail with reference to the accompanying drawings.
1 FIG. is a block diagram of a cloud system and a peripheral configuration, according to an example embodiment.
1 FIG. 10 100 200 Referring to, a systemmay include a plurality of user devicesand a cloud system.
100 100 100 1 100 100 1 100 th th th n n The plurality of user devicesare electronic devices used by users and may perform various operations related to data. The plurality of user devicesmay include first to nuser devices_to_(wherein n is a natural number of 2 or more), and the first to nuser devices_to_may be respectively used by first to nusers.
100 100 100 In an example embodiment, the plurality of user devicesmay be any one of smartphones, tablet PCs, smart TVs, portable phones, personal digital assistants (PDAs), laptops, media players, micro servers, global positioning system (GPS) devices, e-book readers, digital broadcasting terminals, navigation devices, kiosks, MP3 players, digital cameras, home appliances, and other mobile or non-mobile computing devices, but example embodiments are not limited thereto. In addition, the plurality of user devicesmay be wearable devices, such as watches, glasses, hairbands, and rings, each equipped with data processing functions, but example embodiments are not limited thereto, and the plurality of user devicesmay include all types of devices that operate based on an operating system (OS) by using a processor.
100 200 200 100 200 The plurality of user devicesmay store data in the cloud systemand retrieve data stored in the cloud system. The plurality of user devicesmay transmit, to the cloud system, various requests, such as a user sign-up request, a data write request, a data read request, a user withdrawal request, etc.
200 200 200 200 200 The user sign-up request may be a request to allocate space for a user to store data in the cloud system. The data write request may be a request to store data in the cloud system. The data read request may be request to transmit at least some of data stored in the cloud system. The user withdrawal request may be a request to remove all information and data related to a user, which are stored in the cloud system, because the user is no longer using the cloud system.
200 100 200 100 100 The cloud systemmay be a system that stores data used by the plurality of user devices. The cloud systemmay store data according to requests from the plurality of user devicesand may read data according to requests from the plurality of user devicesand transmit the data.
200 200 2 FIG. The cloud systemmay include a plurality of computing devices and a plurality of storage systems. A more detailed structure of the cloud systemmay be described in more detail with reference to.
2 FIG. is a block diagram of a cloud system according to an example embodiment.
2 FIG. 200 210 220 200 230 Referring to, the cloud systemaccording to an example embodiment may include a plurality of computing devicesand a plurality of storage systems. In addition, the cloud systemaccording to an example embodiment may include a network.
210 100 210 210 1 210 th m The plurality of computing devicesmay communicate with the plurality of user devices. The plurality of computing devicesmay include first to mcomputing devices_to_(wherein m is a natural number of 2 or more).
210 100 210 The plurality of computing devicesmay operate based on requests received from the plurality of user devices. The plurality of computing devicesmay perform operations for each of a plurality of users through a plurality of virtual machines.
210 100 100 100 1 1 FIG. The plurality of virtual machines may be included in any one of the plurality of computing devices. The plurality of virtual machines may process requests received from the plurality of user devices. The number of virtual machines may be the same as the number of user devices, and the number of virtual machines may be n in the example embodiment of. Therefore, each of the plurality of virtual machines may process requests received from each of the plurality of user devices, and for example, a first virtual machine among the plurality of virtual machines may process a request received from the first user device_.
210 100 210 100 1 100 The plurality of computing devicesmay receive a user sign-up request from any one of the plurality of user devices. For example, the plurality of computing devicesmay receive a user sign-up request from the first user device_among the plurality of user devices.
210 210 1 210 100 1 100 1 Any one of the plurality of computing devicesmay create a virtual machine therein in response to receiving the user sign-up request. For example, the first computing device_among the plurality of computing devicesmay create the first virtual machine therein in response to receiving a user sign-up request from the first user device_. In some example embodiments, the first virtual machine may process a request received from the first user device_.
220 A virtual machine created in response to a user sign-up request may allocate user storage space within the plurality of storage systemsand may generate mapping information. The user storage space may be space storing user data used by a user. The mapping information may be information about the user storage space.
100 1 220 For example, the first virtual machine created in response to receiving a user sign-up request from the first user device_may allocate, as user storage space, a specific logic block address within a plurality of storage devices (or alternative referred to as a plurality of non-transitory storage devices) in the plurality of storage systems. In some example embodiments, the first virtual machine may allocate the user storage space across the plurality of storage devices (or the plurality of non-transitory storage devices). The first virtual machine may generate mapping information indicating where the allocated user storage space is.
220 The virtual machine created in response to the user sign-up request may transmit the generated mapping information to the plurality of storage systems.
210 100 210 220 The plurality of computing devicesmay receive a data write request or a data read request from any one of the plurality of user devices. The plurality of computing devicesmay transmit the data write request or the data read request to the plurality of storage systems.
210 100 210 100 1 100 The plurality of computing devicesmay receive a user withdrawal request from any one of the plurality of user devices. For example, the plurality of computing devicesmay receive a user withdrawal request from the first user device_among the plurality of user devices.
210 210 100 1 100 In response to receiving the user withdrawal request, the plurality of computing devicesmay remove therefrom a virtual machine that processes a request related to a user, which corresponds to the user withdrawal request. For example, the plurality of computing devicesmay remove the first virtual machine therefrom in response to receiving a user withdrawal request from the first user device_among the plurality of user devices.
210 220 The plurality of computing devicesmay transmit user withdrawal requests to the plurality of storage systems.
220 220 220 1 220 k The plurality of storage systemsmay store data of a plurality of users. The plurality of storage systemsmay include first to kth storage systems_to_(wherein k is a natural number of 2 or more).
220 210 210 220 220 220 210 The plurality of storage systemsmay operate based on requests received from the plurality of computing devices. For example, when receiving data write requests from the plurality of computing devices, the plurality of storage systemsmay store user data of a plurality of users (or the plurality of storage systemsmay store user data of a plurality of users, in response to plurality of storage systemsreceiving data write requests from the plurality of computing devices).
210 220 220 220 210 In an example embodiment, when receiving mapping information from the plurality of computing devices, the plurality of storage systemsgenerate user keys based on the mapping information, and may manage user data to be stored in the plurality of storage devices (or the plurality of non-transitory storage devices) by using the mapping information and the user keys (or the plurality of storage systemsgenerate user keys based on the mapping information, and may manage user data to be stored in the plurality of storage devices by using the mapping information and the user keys, in response to the storage systemsreceiving mapping information from the plurality of computing devices).
210 220 220 220 210 In an example embodiment, when receiving data write requests from the plurality of computing devices, the plurality of storage systemsmay encrypt write data corresponding to the data write requests by using user keys, and may write the encrypted write data to the plurality of storage devices (or the plurality of non-transitory storage devices), based on mapping information (or the plurality of storage systemsmay encrypt write data corresponding to the data write requests by using user keys, and may write the encrypted write data to the plurality of storage devices, based on mapping information, in response to the plurality of storage systemsreceiving data write requests from the plurality of computing devices).
210 220 210 220 210 220 210 In an example embodiment, when reading data write requests from the plurality of computing devices, the plurality of storage systemsmay read encrypted read data corresponding to the data read requests from the plurality of storage devices (or the plurality of non-transitory storage devices), based on mapping information, may decrypt the encrypted read data by using user keys, and may transmit the decrypted read data to the plurality of computing devices(or the plurality of storage systemsmay read encrypted read data corresponding to the data read requests from the plurality of storage devices, based on mapping information, may decrypt the encrypted read data by using user keys, and may transmit the decrypted read data to the plurality of computing devices, in response to the plurality of storage systemsreading write requests from the plurality of computing devices).
210 220 220 220 210 In an example embodiment, when receiving user withdrawal requests from the plurality of computing devices, the plurality of storage systemsmay remove mapping information, user keys, and user data, which correspond to the user withdrawal requests (or the plurality of storage systemsmay remove mapping information, user keys, and user data, which correspond to the user withdrawal requests, in response to the plurality of storage systemsreceiving user withdrawal requests from the plurality of computing devices).
210 220 3 FIG. More detailed structures and operations of each of the plurality of computing devicesand the plurality of storage systemsare described in more detail with reference toand other drawings.
230 210 220 230 210 220 The networkmay wireless connect the plurality of computing devicesto the plurality of storage systems. The networkmay be used as a transmission path for requests, data, etc. between the plurality of computing devicesand the plurality of storage systems.
3 FIG. is a block diagram of detailed structures of a computing device and a storage system, which are included in a cloud system, according to an example embodiment.
3 FIG. 3 FIG. 2 FIG. 3 FIG. 2 FIG. 3 FIG. 300 310 320 310 210 1 210 320 220 1 220 300 310 320 300 th m k Referring to, a cloud systemaccording to an example embodiment may include a computing deviceand a storage system. The computing deviceshown inmay be any one of the first to mcomputing devices_to_shown in. In addition, the storage systemshown inmay be any one of the first to kth storage systems_to_shown in.shows an example embodiment in which the cloud systemincludes one computing deviceand one storage system, but example embodiments are not limited thereto. For example, the cloud systemmay include a plurality of computing devices and a plurality of storage systems.
310 310 1 3 3 FIG. The computing devicemay include a plurality of virtual machines. In the example embodiment of, the computing devicemay include first to third virtual machines VMto VM.
310 1 3 100 1 100 3 310 1 100 1 The computing devicemay create the first to third virtual machines VMto VMin response to user sign-up requests received from the first to third user devices_to_, respectively. For example, the computing devicemay create the first virtual machine VMin response to a user sign-up request received from the first user device_.
1 3 1 100 1 310 320 1 3 The first to third virtual machines VMto VMmay perform operations for first to third users, respectively. For example, the first virtual machine VMmay perform an operation for the first user, based on a request receiving from the first user device_. The computing devicemay transmit a request to the storage systemin response to requests related to the first to third users through the first to third virtual machines VMto VM.
310 1 3 1 3 320 310 1 1 320 The computing devicemay create the first to third virtual machines VMto VMand then allocate first to third user storage spaces USSto USSwithin the storage system. For example, the computing devicemay create the first virtual machine VMand then allocate the first user storage space USSinside the storage system.
310 1 3 1 3 The computing devicemay allocate the first to third user storage spaces USSto USSand then generate mapping information. The mapping information may include information about the first to third user storage spaces USSto USSallocated to each of a plurality of users.
310 320 310 320 The computing devicemay transmit the mapping information to the storage system. In some example embodiments, the computing devicemay transmit the mapping information to the storage systemby using a command line interface (CLI), a representational state transfer (RESTful) application programming interface (API), etc.
320 320 310 The storage systemmay store data about the first to third users. The storage systemmay be wirelessly connected to the computing devicethrough a network.
320 322 323 321 1 321 4 3 FIG. The storage systemmay include a plurality of storage devices (or alternatively referred to as a plurality of non-transitory storage devices), a controller, and a memory.shows an example embodiment in which the plurality of storage devices (or the plurality of non-transitory storage devices) includes four storage devices by including first to fourth storage devices_to_, but inventive concepts are not limited thereto, and the plurality of storage devices may include two storage devices, three storage devices, or at least five storage devices.
321 1 321 4 321 1 321 4 321 1 321 4 321 1 321 4 The first to fourth storage devices_to_may store data used by a plurality of users. In an example embodiment, the first to fourth storage devices_to_may be any one of various types of storage devices, such as SSDs, embedded universal flash storage (UFS) memory devices, or embedded multi-media cards (eMMCs). Each of the first to fourth storage devices_to_may perform an encryption function (for example, self-encrypting drive (SED)), and accordingly, data to be stored in the first to fourth storage devices_to_may be encrypted and then stored.
321 1 321 4 1 3 1 3 In an example embodiment, the first to fourth storage devices_to_may include the first to third user storage spaces USSto USSallocated to each of a plurality of users. The first to third user storage spaces USSto USSmay store user data used by each of a plurality of users.
3 FIG. 310 1 3 321 1 321 4 1 3 1 321 1 321 2 2 321 1 321 3 321 4 3 321 2 321 3 321 4 In the example embodiment of, the computing deviceincludes the first to third virtual machines VMto VMthat perform operations for the first to third users, and thus, the first to fourth storage devices_to_may include the first to third user storage spaces USSto USS. In some example embodiments, the first user storage space USSmay be allocated to the first storage device_and the second storage device_, the second user storage space USSmay be allocated to the first storage device_, the third storage device_, and the fourth storage device_, and the third user storage space USSmay be allocated to the second storage device_, the third storage device_, and the fourth storage device_. As such, any one user storage space may not be allocated within one storage device, and any one user storage space may not be allocated within all storage devices.
322 320 322 310 The controllermay control the overall operation of the storage system. The controllermay operate based on information and a request, which are received from the computing device.
322 310 In an example embodiment, the controllermay receive mapping information from the computing device.
1 3 100 1 100 1 3 321 1 321 4 1 3 th n The mapping information may be information about the first to third user storage spaces USSto USSand may indicate which of the first to nuser devices_to_uses the first to third user storage spaces USSto USS, and which of the first to fourth storage devices_to_contain the first to third user storage spaces USSto USS.
In an example embodiment, the mapping information may include at least one of user storage space identification information, computing device identification information, virtual machine identification information, storage system identification information, storage device identification information, and logic block address information.
1 3 The user storage space identification information may be information that identifies the first to third user storage spaces USSto USS.
300 The computing device identification information may be information that identifies which of the plurality of computing devices included in the cloud systemis a computing device including a virtual machine that processes a request by a user using a specific user storage space.
1 3 310 The virtual machine identification information may be information that identifies which of the first to third virtual machines VMto VMincluded in the computing deviceis a virtual machine that processes a request by a user using a specific user storage space.
300 The storage system identification information may be information that identifies which of the plurality of storage systems included in the cloud systemis a storage system including a specific user storage space.
321 1 321 4 The storage device identification information may be information that identifies which of the first to fourth storage devices_to_is a storage device including a specific user storage space.
321 1 321 4 The logic block address information may be information indicating a logic block address in which a specific user storage space is located in the first to fourth storage devices_to_.
4 FIG. An example of mapping information is described later with reference to.
322 322 322 In an example embodiment, when receiving mapping information, the controllermay generate a user key, based on the mapping information (or the controllermay generate a user key, based on the mapping information, in response to the controllerreceiving mapping information).
321 1 321 4 321 1 321 4 The user key may be a key used to encrypt and decrypt user data. The first to fourth storage devices_to_may encrypt user data by using user keys and store the encrypted user data therein. In addition, the first to fourth storage devices_to_may decrypt the encrypted user data by using user keys and transmit the decrypted user data to the outside.
322 1 3 322 1 2 In an example embodiment, the controllermay generate different user keys for each of the first to third user storage spaces USSto USS, based on mapping information. For example, the controllermay generate different user keys, one of which is used to encrypt user data to be stored in the first user storage space USS, and the other of which is used to encrypt user data to be stored in the second user storage space USS.
4 FIG. An example of a user key corresponding to mapping information is described later with reference to.
322 321 1 321 4 In an example embodiment, the controllermay manage user data stored in the first to fourth storage devices_to_by using mapping information and user keys.
322 321 1 321 4 310 The controllermay determine, by using mapping information, which logic block address within which of the first to fourth storage devices_to_stores user data corresponding to a request received from the computing device.
322 321 1 321 4 321 1 321 4 In addition, the controllermay encrypt user data to be stored in the first to fourth storage devices_to_by using user keys and decrypt the encrypted user data stored in the first to fourth storage devices_to_by using user keys.
322 310 321 1 321 4 In an example embodiment, the controllermay receive a data write request from the computing device. The data write request may be a request to store write data in the first to fourth storage devices_to_.
322 1 3 310 322 1 3 310 322 322 322 In some example embodiments, when receiving the data write request, the controllermay determine which of the first to third virtual machines VMto VMincluded in the computing deviceis a virtual machine that has transmitted the data write request (or the controllermay determine which of the first to third virtual machines VMto VMincluded in the computing deviceis a virtual machine that has transmitted the data write request, in response to the controllerreceiving the data write request). The controllermay select a user key used to encrypt user data to be stored in user storage space used by the virtual machine that has transmitted the data write request. The controllermay encrypt write data corresponding to the data write request by using the selected user key.
1 322 1 322 1 1 For example, when the virtual machine that has transmitted the data write request is the first virtual machine VM, the controllermay encrypt the write data by using a user key used to encrypt user data to be stored in the first user storage space USS(or the controllermay encrypt the write data by using a user key used to encrypt user data to be stored in the first user storage space USS, based on the virtual machine that has transmitted the data write request being the first virtual machine VM).
322 321 1 321 4 322 321 1 321 4 Next, the controllermay determine, based on mapping information, where the user storage space, in which the encrypted write data is to be stored, exists among the first to fourth storage devices_to_. The controllermay write the encrypted write data to the first to fourth storage devices_to_, based on a result of the determination.
1 322 1 321 1 321 2 322 1 321 1 321 2 1 322 321 1 321 2 For example, when the virtual machine that has transmitted the data write request is the first virtual machine VM, the controllermay determine that the first user storage space USSexists in the first storage device_and the second storage device_, based on mapping information (or the controllermay determine that the first user storage space USSexists in the first storage device_and the second storage device_, based on mapping information, based on the virtual machine that has transmitted the data write request being the first virtual machine VM). The controllermay write the encrypted write data to any one of the first storage device_and the second storage device_.
322 310 321 1 321 4 In an example embodiment, the controllermay receive a data read request from the computing device. The data read request may be a request to read read data from the first to fourth storage devices_to_.
322 1 3 310 322 1 3 310 322 322 321 1 321 4 322 321 1 321 4 In some example embodiments, when receiving the data read request, the controllermay determine which of the first to third virtual machines VMto VMincluded in the computing deviceis a virtual machine that has transmitted the data read request (or the controllermay determine which of the first to third virtual machines VMto VMincluded in the computing deviceis a virtual machine that has transmitted the data read request, in response to the controllerreceiving the data read request). The controllermay determine, based on mapping information, where user storage space, which is used by the virtual machine that has transmitted the data read request, exists among the first to fourth storage devices_to_. The controllermay read encrypted read data corresponding to the data read request from the first to fourth storage devices_to_, based on a result of the determination.
1 322 1 321 1 321 2 322 1 321 1 321 2 1 322 321 1 321 2 For example, when the virtual machine that has transmitted the data read request is the first virtual machine VM, the controllermay determine that the first user storage space USSexists in the first storage device_and the second storage device_(or the controllermay determine that the first user storage space USSexists in the first storage device_and the second storage device_, based on the virtual machine that has transmitted the data write request being the first virtual machine VM). The controllermay read the encrypted read data from any one of the first storage device_and the second storage device_.
322 322 321 1 321 4 The controllermay select a user key used to encrypt user data stored in user storage space used by the virtual machine that has transmitted the data read request. The controllermay decrypt the encrypted read data read from the first to fourth storage devices_to_, by using the selected user key.
1 322 1 322 1 1 For example, when the virtual machine that has transmitted the data read request is the first virtual machine VM, the controllermay decrypt the encrypted read data by using a user key used to encrypt user data stored in the first user storage space USS(or the controllermay decrypt the encrypted read data by using a user key used to encrypt user data stored in the first user storage space USS, based on the virtual machine that has transmitted the data read request being the first virtual machine VM).
322 310 The controllermay transmit the decrypted read data to the computing device.
322 In an example embodiment, the controllermay determine whether to encrypt user data by using a user key, based on setting of whether to use an encryption function by each of a plurality of users.
321 1 321 4 The setting of whether to use the encryption function may be setting of whether to encrypt user data before storing the user data in the first to fourth storage devices_to_.
322 321 1 321 4 322 310 322 310 322 In some example embodiments, when set to use the encryption function, the controllermay encrypt write data as described above and store the encrypted write data in the first to fourth storage devices_to_. In addition, when set to use the encryption function, the controllermay decrypt read data as described above and transmit the decrypted read data to the computing device(or the controllermay decrypt read data as described above and transmit the decrypted read data to the computing device, based on the controllerbeing set to use the encryption function).
322 321 1 321 4 322 321 1 321 4 322 322 310 322 310 322 In some example embodiments, when set not to use the encryption function, the controllermay not encrypt write data corresponding to a data write request and may store the write data in the first to fourth storage devices_to_(or the controllermay not encrypt write data corresponding to a data write request and may store the write data in the first to fourth storage devices_to_, based on the controllernot being set to use the encryption function). In addition, when set not to use the encryption function, the controllermay not decrypt read data corresponding to a data read request and transmit the read data to the computing device(or the controllermay not decrypt read data corresponding to a data read request and transmit the read data to the computing device, based on the controllernot being set to use the encryption function).
310 322 322 322 310 In an example embodiment, when receiving a user withdrawal request from the computing device, the controllermay remove mapping information, user keys, and user data, which correspond to the user withdrawal request (or the controllermay remove mapping information, user keys, and user data, which correspond to the user withdrawal request, in response to the controllerreceiving a user withdrawal request from the computing device). In some example embodiments, the user withdrawal request may be received through a non-volatile memory express (NVMe)-type command, a dataset management (DSM) command, etc.
322 322 322 In some example embodiments, when receiving the user withdrawal request, the controllermay check information related to a user who is the subject of the user withdrawal request, and may remove all information related to the user (or the controllermay check information related to a user who is the subject of the user withdrawal request, and may remove all information related to the user, in response to the controllerreceiving the user withdrawal request).
322 1 1 322 1 1 322 For example, when receiving a user withdrawal request related to the first user, the controllermay remove information related to the first user among mapping information, a user key used to encrypt the first user storage space USS, and user data stored in the first user storage space USS(or the controllermay remove information related to the first user among mapping information, a user key used to encrypt the first user storage space USS, and user data stored in the first user storage space USS, in response to the controllerreceiving a user withdrawal request related to the first user).
323 322 The memorymay store data used by the controller.
323 310 323 323 323 310 323 322 322 In an example embodiment, the memorymay store mapping information. In some example embodiments, when receiving mapping information from the computing device, the memorymay store the mapping information therein (or the memorymay store the mapping information therein, in response to the memoryreceiving mapping information from the computing device). The mapping information stored in the memorymay be read by the controllerand used for various operations of the controller.
323 320 323 The memorymay include volatile memory, such as static random access memory (SRAM), dynamic random access memory (DRAM), etc. Therefore, like a case where the storage systemis reset or rebooted, when power supply is interrupted and then resumed, all data stored in the memorymay be removed.
320 322 310 322 310 320 322 310 In an example embodiment, when the storage systemis reset or rebooted, the controllermay transmit a mapping information request to the computing device(or the controllermay transmit a mapping information request to the computing device, in response to the storage systembeing reset or rebooted). In some example embodiments, the controllermay transmit the mapping information request to the computing deviceby using a CLI, RESTful API, etc.
320 323 322 310 323 322 310 310 322 310 The mapping information request may be a request to transmit mapping information. In some example embodiments, when the storage systemis reset or rebooted, all mapping information stored in the memoryis removed, and thus, the controllermay transmit a mapping information request to the computing deviceto re-obtain mapping information (or all mapping information stored in the memoryis removed, and thus, the controllermay transmit a mapping information request to the computing deviceto re-obtain mapping information, in response to the storage system being reset or rebooted). In response to receiving the mapping information request, the computing devicemay transmit the mapping information. Accordingly, the controllermay receive the mapping information from the computing device.
320 320 In some example embodiments, when the storage system, according to some example embodiments of inventive concepts described above, user data stored in the storage systemmay be safely managed (or may be managed) by receiving mapping information, generating a user key, based on the received mapping information, and managing user data by using the mapping information and the user key.
4 FIG. is a diagram of an example of mapping information and user keys, which are used in a storage system, according to an example embodiment.
4 FIG. 3 FIG. 4 FIG. 3 FIG. 300 310 310 320 320 Referring to, an example of mapping information and user keys, which are used in the cloud systemas shown in, may be checked. In some example embodiments, the mapping information inmay be an example embodiment in which the computing deviceofis a first computing deviceand the storage systemis a first storage system.
The mapping information may include user storage space identification information USS ID, computing device identification information CD ID, virtual machine identification information VM ID, storage system identification information SS ID, storage device identification information SD ID, and logic block address information LBA.
1 1 1 310 1 1 1 321 1 321 2 320 1 1 1 321 1 321 2 1 1 1 2 The user storage space identification information USS ID of the first user storage space USSmay be 1. A request for the first user storage space USSis transmitted from the first virtual machine VMof the first computing device, and thus, the computing device identification information CD ID corresponding to the first user storage space USSmay be all 1, and the virtual machine identification information VM ID corresponding to the first user storage space USSmay be all 1. The first user storage space USSis allocated to the first storage device_and the second storage device_within the first storage system, and thus, the storage system identification information SS ID corresponding to the first user storage space USSmay be all 1, and the storage device identification information SD ID corresponding to the first user storage space USSmay be respectively 1 and 2. The first user storage space USSis located in the uppermost logic block of the first storage device_and the second storage device_, and thus, the logic block address information LBA corresponding to the first user storage space USSmay all be 0 to 0x0FFF. User keys stored in the first user storage space USSmay be Aand A.
2 2 2 310 2 2 2 321 1 321 3 321 4 320 2 2 2 321 1 321 3 321 4 2 321 1 2 321 3 321 4 2 1 2 3 The user storage space identification information USS ID of the second user storage space USSmay be 2. A request for the second user storage space USSis transmitted from the second virtual machine VMof the first computing device, and thus, the computing device identification information CD ID corresponding to the second user storage space USSmay be all 1, and the virtual machine identification information VM ID corresponding to the second user storage space USSmay be all 2. The second user storage space USSis allocated to the first storage device_, the third storage device_, and the fourth storage device_within the first storage system, and thus, the storage system identification information SS ID corresponding to the second user storage space USSmay be all 1, and the storage device identification information SD ID corresponding to the second user storage space USSmay be respectively 1, 3, and 4. The second user storage space USSis located in the second top logic block of the first storage device_and the uppermost logic block of the third storage device_and the fourth storage device_, and thus, the logic block address information LBA of the second user storage space USS, which corresponds to the first storage device_, may be 0x1000 to 0x1FFF, and the logic block address information LBA of the second user storage space USS, which corresponds to the third storage device_and the fourth storage device_, may be all 0 to 0x0FFF. User keys stored in the second user storage space USSmay be B, B, and B.
3 3 3 310 3 3 3 321 2 321 3 321 4 320 3 3 3 321 1 321 3 321 4 3 3 1 2 3 The user storage space identification information USS ID of the third user storage space USSmay be 3. A request for the third user storage space USSis transmitted from the third virtual machine VMof the first computing device, and thus, the computing device identification information CD ID corresponding to the third user storage space USSmay be all 1, and the virtual machine identification information VM ID corresponding to the third user storage space USSmay be all 3. The third user storage space USSis allocated to the second storage device_, the third storage device_, and the fourth storage device_within the first storage system, and thus, the storage system identification information SS ID corresponding to the third user storage space USSmay be all 1, and the storage device identification information SD ID corresponding to the third user storage space USSmay be respectively 2, 3, and 4. The third user storage space USSis located in the second top logic block of the first storage device_, the third storage device_, and the fourth storage device_, and thus, the logic block address information LBA corresponding to the third user storage space USSmay be all 0x1000 to 0x1FFF. User keys stored in the third user storage space USSmay be C, C, and C.
5 FIG. is a flowchart showing an operating method of a storage system, according to an example embodiment.
5 FIG. 510 320 320 310 322 310 320 310 320 310 Referring to, in operation S, the storage systemmay receive mapping information. The storage systemmay receive mapping information from the computing devicethrough the controller. In some example embodiments, when receiving a user sign-up request from a user device, the computing devicemay generate mapping information and transmit the generated mapping information to the storage system(or the computing devicemay generate mapping information and transmit the generated mapping information to the storage system, in response to the computing devicereceiving a user sign-up request from a user device).
520 320 320 323 322 In operation S, the storage systemmay store the mapping information. The storage systemmay store the received mapping information in the memorythrough the controller.
530 320 320 1 3 322 In operation S, the storage systemmay generate user keys, based on the mapping information. The storage systemmay generate different user keys for each of the first to third user storage spaces USSto USSthrough the controller, based on the mapping information.
540 320 320 310 322 320 310 322 In operation S, the storage systemmay manage user data by using the mapping information and the user keys. The storage systemmay encrypt write data corresponding to a data write request received from the computing devicethrough the controller, by using the mapping information and the user keys. In addition, the storage systemmay decrypt read data corresponding to a data read request received from the computing devicethrough the controller, by using the mapping information and the user keys.
6 FIG. is a flowchart showing an operating method when a new user signs up in a cloud system, according to an example embodiment.
6 FIG. 610 400 510 510 400 Referring to, in operation S, a user devicemay transmit a user sign-up request to a computing device. The computing devicemay receive, from the user device, a request to allocate space for a new user to store data.
620 510 510 400 400 In operation S, the computing devicemay create a virtual machine. The computing devicemay create a virtual machine to process a request received from the user device, in response to receiving the user sign-up request from the user device.
630 510 510 520 400 In operation S, the computing devicemay allocate user storage space. The computing devicemay allocate, within a storage system, user storage space in which user data is to be stored, in response to receiving the user sign-up request from the user device.
640 510 510 630 In operation S, the computing devicemay generate mapping information. The computing devicemay generate mapping information including information about the user storage space allocated in operation S.
650 510 520 520 510 In operation S, the computing devicemay transmit the mapping information to the storage system. The storage systemmay receive, from the computing device, the mapping information generated according to the user sign-up request.
660 520 660 520 6 FIG. 5 FIG. In operation S, the storage systemmay store the mapping information. The operation in operation Sofmay be the same as the operation in operation Sof.
670 520 670 560 6 FIG. 5 FIG. In operation S, the storage systemmay generate user keys. The operation in operation Sofmay be the same as the operation in operation Sof.
680 520 680 540 6 FIG. 5 FIG. In operation S, the storage systemmay manage user data. The operation in operation Sofmay be the same as the operation in operation Sof.
7 FIG. is a flowchart showing an operating method when data is written to a storage system, according to an example embodiment.
7 FIG. 710 320 320 310 Referring to, in operation S, the storage systemmay receive a data write request. The storage systemmay receive, from the computing device, a data write request generated by a user device. The data write request may include write data.
720 320 320 322 In operation S, the storage systemmay encrypt the write data by using user keys. The storage systemmay encrypt the write data by using user keys used to encrypt user storage space used by the user device that has transmitted the data write request through the controller.
730 320 320 321 1 321 4 322 321 1 321 4 In operation S, the storage systemmay write the write data to a plurality of storage devices (or alternatively referred to as a plurality of non-transitory storage devices), based on mapping information. The storage systemmay determine, based on the mapping information, where the user storage space, in which the encrypted write data is to be stored, exists among the first to fourth storage devices (or non-transitory storage devices)_to_through the controller, and may write the encrypted write data to the first to fourth storage devices_to_, based on a result of the determination.
8 FIG. is a flowchart showing an operating method when data is read from a storage system, according to an example embodiment.
8 FIG. 810 320 320 310 Referring to, in operation S, the storage systemmay receive a data read request. The storage systemmay receive, from the computing device, a data read request generated by a user device. The data read request may include information about read data.
820 320 320 321 1 321 4 322 321 1 321 4 In operation S, the storage systemmay read encrypted read data from the plurality of storage devices, based on mapping information. The storage systemmay determine, based on mapping information, where user storage space, in which the encrypted read data is stored, exists among the first to fourth storage devices_to_through the controller, and may read the encrypted read data to from the first to fourth storage devices_to_, based on a result of the determination.
830 320 320 322 In operation S, the storage systemmay decrypt the encrypted read data by using user keys. The storage systemmay decrypt the encrypted read data by using user keys used to encrypt user storage space used by the user device that has transmitted the data read request through the controller.
840 320 310 320 310 322 310 In operation S, the storage systemmay transmit the decrypted read data to the computing device. The storage systemmay transmit the decrypted read data to the computing devicethrough the controller, and accordingly, the computing devicemay transmit the decrypted read data to the user device.
9 FIG. is a flowchart showing an operating method when a storage system is reset or rebooted, according to an example embodiment.
9 FIG. 910 320 320 323 320 310 322 323 320 310 322 320 Referring to, in operation S, the storage systemmay transmit a mapping information request. In some example embodiments, when the storage systemis reset or rebooted, all mapping information stored in the memoryis removed, and thus, the storage systemmay transmit a mapping information request to the computing devicethrough the controller(or all mapping information stored in the memoryis removed, and thus, the storage systemmay transmit a mapping information request to the computing devicethrough the controller, in response to the storage systembeing reset or rebooted).
920 320 920 510 9 FIG. 5 FIG. In operation S, the storage systemmay receive mapping information. The operation in operation Sofmay be the same as the operation in operation Sof.
930 320 930 520 9 FIG. 5 FIG. In operation S, the storage systemmay store the mapping information. The operation in operation Sofmay be the same as the operation in operation Sof.
940 320 940 530 9 FIG. 5 FIG. In operation S, the storage systemmay generate user keys, based on the mapping information. The operation in operation Sofmay be the same as the operation in operation Sof.
950 320 950 540 9 FIG. 5 FIG. In operation S, the storage systemmay manage user data by using the mapping information and the user keys. The operation in operation Sofmay be the same as the operation in operation Sof.
10 FIG. is a flowchart showing an operating method when a user withdraws from a cloud system, according to an example embodiment.
10 FIG. 1010 400 510 510 400 500 Referring to, in operation S, the user devicemay transmit a user withdrawal request to the computing device. The computing devicemay receive, from the user device, a request indicating that the existing user is no longer using a cloud system.
1020 510 510 In operation S, the computing devicemay remove a virtual machine. The computing devicemay remove therefrom the virtual machine that processes a request related to a user, which corresponds to the user withdrawal request.
1030 510 520 520 510 400 In operation S, the computing devicemay transmit the user withdrawal request to the storage system. The storage systemmay receive, from the computing device, the user withdrawal request transmitted from the user device.
1040 520 520 322 In operation S, the storage systemmay remove mapping information. The storage systemmay remove mapping information related to user storage space, which corresponds to the user withdrawal request, through the controller.
1050 520 520 322 In operation S, the storage systemmay remove user keys. The storage systemmay remove user keys used to encrypt user data stored in the user storage space through the controller, the user keys corresponding to the user withdrawal request.
1060 520 520 322 In operation S, the storage systemmay remove user data. The storage systemmay remove all user data stored in the user storage space, which corresponds to the user withdrawal request, through the controller.
One or more of the elements disclosed above may include or be implemented in processing circuitry such as hardware including logic circuits; a hardware/software combination such as a processor executing software; or a combination thereof. For example, the processing circuitry more specifically may include, but is not limited to, a central processing unit (CPU), an arithmetic logic unit (ALU), a digital signal processor, a microcomputer, a field programmable gate array (FPGA), a System-on-Chip (SoC), a programmable logic unit, a microprocessor, application-specific integrated circuit (ASIC), etc.
While inventive concepts have been particularly shown and described with reference to example embodiments thereof, it will be understood that various changes in form and details may be made therein without departing from the spirit and scope of the following claims.
Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.
October 28, 2024
September 8, 2026
Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.